Screen unlocked with userID:. · regex sendBSDNotification: \w+.\w+.\w+.screenIsUnlocked


Description

Screen unlocked with userID:$(userID).

Query · wazuh

decoded_as=macOS_loginwindow AND regex="sendBSDNotification: \w+.\w+.\w+.screenIsUnlocked"
Raw source Screen unlocked with userID:. · regex sendBSDNotification: \w+.\w+.\w+.screenIsUnlocked · Wazuh XML
Esc
Published by Wazuh Core Ruleset ↗, licensed under GPLv2 ↗. Reproduced here unmodified.
<rule id="89602" level="3">
    <decoded_as>macOS_loginwindow</decoded_as>
    <regex type="pcre2">sendBSDNotification: \w+.\w+.\w+.screenIsUnlocked</regex>
    <description>Screen unlocked with userID:$(userID).</description>
    <mitre>
      <id>T1078</id>
    </mitre>
    <group>authentication_success,gdpr_IV_32.2,gpg13_7.1,gpg13_7.2,hipaa_164.312.b,nist_800_53_AC.7,nist_800_53_AU.14,pci_dss_10.2.5,tsc_CC6.8,tsc_CC7.2,tsc_CC7.3,</group>
  </rule>

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.